QID 378087

Date Published: 2023-03-20

QID 378087: Zoom Rooms Information Disclosure Vulnerability (ZSB-23001)

Zoom Rooms is a software-based room system that provides an integrated experience for audio conferencing, wireless screen sharing, and video conferencing.

Zoom Rooms for Windows clients before version 5.13.5 contain an information disclosure vulnerability.

Affected Versions:
Zoom Rooms for Windows clients before version 5.13.5

QID Detection Logic:
Windows: This authenticated QID detects vulnerable version of Zoom Rooms using registry "HKLM\SOFTWARE\Classes\zoomroom\DefaultIcon" and "HKLM\SOFTWARE\WOW6432Node\Classes\zoomroom\DefaultIcon"

Successful exploitation of this vulnerability may allows a remote attacker to gain access to potentially sensitive information.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to upgrade to Zoom Rooms 5.13.3 or later to remediate these vulnerabilities.

    CVEs related to QID 378087

    Software Advisories
    Advisory ID Software Component Link
    ZSB-23001 URL Logo explore.zoom.us/en/trust/security/security-bulletin/